Security: Containerpak/cpak
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Exported wrapper scripts are built from an unvalidated binary nameGHSA-6m9p-wvxc-wp5v published
Aug 19, 2026 by mirkobrombinLow -
The owned-container check validates a name that is resolved again by the container engineGHSA-5pq9-489r-xg55 published
Aug 19, 2026 by mirkobrombinLow -
The store tree is world-readable, exposing what applications writeGHSA-rw5w-c99w-h5c9 published
Aug 19, 2026 by mirkobrombinLow -
A declared permission prevents the container from startingGHSA-gmc8-j3vv-xm9m published
Aug 19, 2026 by mirkobrombinLow -
A layer fetched through the chunked path is never bound, leaving the package unlaunchableGHSA-j2v9-h5w2-wxj4 published
Aug 19, 2026 by mirkobrombinLow -
Child descriptors of an OCI image index are never validated, so a digest-pinned reference can stop pinningGHSA-wjf6-3r2h-vf9g published
Aug 19, 2026 by mirkobrombinModerate -
Time-of-check to time-of-use on the mount path passed to the container engineGHSA-hgmc-5cgc-j997 published
Aug 19, 2026 by mirkobrombinModerate -
The file chooser portal reply is not authenticated against the senderGHSA-j8v4-xjqg-v72g published
Aug 19, 2026 by mirkobrombinModerate -
The restricted desktop bus proxy forwards every message that is not a method callGHSA-5cg5-hrhr-3cpp published
Aug 19, 2026 by mirkobrombinModerate -
Forgetting one's own integrity anchor removes the anti-rollback floorGHSA-p953-5q4r-3j4p published
Aug 19, 2026 by mirkobrombinModerate
Learn more about advisories related to Containerpak/cpak in the GitHub Advisory Database